VendorsProgresssitefinityany version
Vulnerabilities

Progress Sitefinity any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2026-7312
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity
Published 2026-06-02 · Analyzed
10.0EPSS 0.006
CVE-2017-9248
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.
Published 2017-07-03 · Analyzed
9.8KEV1 PoCEPSS 0.751
CVE-2019-17392
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
Published 2019-11-26 · Modified
9.8EPSS 0.011
CVE-2023-29375
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.
Published 2023-04-10 · Modified
9.8EPSS 0.008
CVE-2026-7198
CWE-284: Improper Access Control in web services in Progress Sitefinity
Published 2026-06-02 · Analyzed
9.8EPSS 0.006
CVE-2026-7195
CWE-20: Improper Input Validation in web services in Progress Sitefinity
Published 2026-06-02 · Analyzed
8.8EPSS 0.006
CVE-2026-7201
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity
Published 2026-06-02 · Analyzed
8.8EPSS 0.005
CVE-2024-1632
Incorrect access control in the Sitefinity backend
Published 2024-02-28 · Analyzed
8.8EPSS 0.005
CVE-2026-7313
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity
Published 2026-06-02 · Analyzed
8.7EPSS 0.005
CVE-2024-11626
Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
Published 2025-01-07 · Analyzed
8.4EPSS 0.004
CVE-2024-11627
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
Published 2025-01-07 · Analyzed
8.1EPSS 0.003
CVE-2024-1636
Potential Cross-Site Scripting (XSS) in the page editing area
Published 2024-02-28 · Analyzed
8.0EPSS 0.004
CVE-2024-11625
Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
Published 2025-01-07 · Analyzed
7.7EPSS 0.003
CVE-2018-17055
An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.
Published 2018-09-28 · Modified
7.5EPSS 0.010
CVE-2023-27636
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
Published 2024-06-16 · Modified
6.51 PoCEPSS 0.013
CVE-2019-7215
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.
Published 2019-06-06 · Modified
6.5EPSS 0.010
CVE-2023-29376
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in Sitefinity to media libraries.
Published 2023-04-10 · Modified
5.4EPSS 0.004
CVE-2023-6784
Potential Use of the Sitefinity System for Distribution of Phishing Emails
Published 2023-12-20 · Modified
4.7EPSS 0.004